CVE-2024-47807

Severity CVSS v4.0:
Pending analysis
Type:
CWE-287 Authentication Issues
Publication date:
02/10/2024
Last modified:
06/05/2025

Description

Jenkins OpenId Connect Authentication Plugin 4.354.v321ce67a_1de8 and earlier does not check the `iss` (Issuer) claim of an ID Token, allowing attackers to subvert the authentication flow, potentially gaining administrator access to Jenkins.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:jenkins:openid_connect_authentication:*:*:*:*:*:jenkins:*:* 4.355.v3a_fb_fca_b_96d4 (excluding)